Cybersecurity risk governance and fraud management in invoice-tax data sharing for credit scoring: A tripartite framework for Vietnam
Main Article Content
Abstract
Purpose - Decree 70/2025 and Decree 94/2025 in Vietnam established a tripartite data pipeline that shares real-time e-invoices from the General Department of Taxation (GDT) to credit institutions for enterprise credit scoring. Prevailing Third-Party Risk Management (TPRM) frameworks, including DORA, NIST CSF 2.0, the FSB TPRM Toolkit, and BIS BCBS d577, address private-sector relationships and do not cover risks specific to government-as-data-provider architectures, such as non-terminability, monopoly provision, and accountability fragmentation. No existing TPRM standard accounts for a government agency serving as the sole, non-terminable data source in private-sector credit scoring, leaving this configuration in a governance vacuum.
Method - Using Design Science Research (DSR) methodology, we conducted a comparative regulatory analysis of Decree 94/2025 and constructed a threat taxonomy. Building on this taxonomy, we designed the Tripartite Governance Framework for Vietnam (TGF-VN v1.0) through analogical transfer from HIPAA, Singapore's MyInfo, and the SWIFT Customer Security Controls Framework.
Findings - Our analysis identifies 10 regulatory gaps in areas including API security, accountability, and breach notification, and 16 threat vectors across API, transmission, and invoice-fraud layers. TGF-VN v1.0 comprises 12 integrated controls that address these exposures and provide the structural basis for the State Bank of Vietnam's (SBV) implementing circulars.
Originality - The framework also yields a replicable governance template for similar government-data-sharing initiatives across ASEAN and emerging markets.
Keywords
Credit scoring; Cybersecurity governance; Invoice fraud; Tax data sharing; Third-Party risk management
Article Details
Field of Economic (JEL Codes)
G21 - Banks • Depository Institutions • Micro Finance Institutions • Mortgages - G28 - Government Policy and Regulation - Financial Institutions and Services, K22 - Business and Securities Law - Regulation and Business Law, O38 - Government Policy - Innovation • Research and Development • Technological Change • Intellectual Property Rights
References
Chen, Y., Zhao, C., Xu, Y., Nie, C., & Zhang, Y. (2025). Year-over-year developments in financial fraud detection via deep learning: A systematic literature review. arXiv, 2502.00201. https://doi.org/10.48550/arXiv.2502.00201
European Parliament (2025). Digital Operational Resilience Act (DORA), EU Regulation 2022/2554. https://www.digital-operational-resilience-act.com/
European Payments Council (2023). 2023 payments threats and fraud trends report. EPC.
Financial Stability Board (2023). Final report: Enhancing third-party risk management and oversight — A toolkit for financial institutions and financial authorities. FSB. https://www.fsb.org/2023/12/
Gentner, D. (1983). Structure-mapping: A theoretical framework for analogy. Cognitive Science, 7(2), 155–170. https://doi.org/10.1207/s15516709cog0702_3
Hernandez Aros, L., Bustamante Molano, L. X., Gutierrez-Portela, F., Moreno Hernandez, J. J., & Rodríguez Barrero, M. S. (2024). Financial fraud detection through the application of machine learning techniques: A literature review. Humanities and Social Sciences Communications, 11(1), 1–22. https://doi.org/10.1057/s41599-024-03606-0
Hevner, A. R., March, S. T., Park, J., & Ram, S. (2004). Design science in information systems research. MIS Quarterly, 28(1), 75–105. https://dl.acm.org/doi/10.5555/2017212.2017217
IFC & SME Finance Forum (2025). MSME Finance Gap: An Updated Estimation and Evolution of the MSME Finance Gap in Emerging Markets and Developing Economies. https://www.smefinanceforum.org/data-sites/msme-finance-gap
Modesti, P., Freitas, L., Shotomiwa, Q., & Almehrej, A. (2025). Security analysis of the open banking account and transaction API protocol. Cyber Security and Applications. https://doi.org/10.1016/j.csa.2025.100097
NIST (2024). Cybersecurity framework 2.0 (NIST.CSWP.29). https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf
OCC/FDIC/Federal Reserve (2023). Interagency guidance on third-party relationships: Risk management. https://www.fdic.gov/news/financial-institution-letters/2023/fil23029.html
OWASP (2023). API security top 10. Open Web Application Security Project.
Ojehomon, O. G., Cichorska, J., & Michnik, J. (2026). Cyber Risk Management of API-Enabled Financial Crime in Open Banking Services. Entropy, 28(2), 163. https://doi.org/10.3390/e28020163
Peisert, S., Schneier, B., Okhravi, H., Massacci, F., Benzel, T., Landwehr, C., Mannan, M., Mirkovic, J., Prakash, A., & Michael, J. B. (2021). Perspectives on the SolarWinds incident. IEEE Security & Privacy, 19(2), 7–13. https://doi.org/10.1109/MSEC.2021.3051235
Peffers, K., Tuunanen, T., Rothenberger, M., & Chatterjee, S. (2007). A design science research methodology for information systems research. Journal of Management Information Systems, 24(3), 45–77. https://doi.org/10.2753/MIS0742-1222240302
Snyder, H. (2019). Literature review as a research methodology: An overview and guidelines. Journal of Business Research, 104, 333–339. https://doi.org/10.1016/j.jbusres.2019.07.039